3 ms·
It's not always possible to get certificates from Let's Encrypt for local network only services. In a big corporate environment jumping through the hoops necess
by opk 5y ago
It's not always possible to get certificates from Let's Encrypt for local network only services. In a big corporate environment jumping through the hoops necessary to deploy keys or get things into a DMZ can be near impossible. Even if you don't have those issues it is still one more thing to learn and setup. All these things pile up. Try setting up a basic e-mail server on the modern Internet and compare that to 20 years ago.
- easton 5y agoIf your company has network admins smart enough to deploy segmentation rules, they are also probably smart enough to setup a internal CA and deploy the certs to everyone’s root store. If not, that stinks. Smallstep makes a basic CA for free that is ACME compliant, meaning you just need to change the URL for Let’s Encrypt on your server and restart. Microsoft also has a CA included with Windows Server if you’re using that which works fine (although it uses a different API to get certs).
- hannob 5y ago> In a big corporate environment jumping through the hoops necessary to deploy keys or get things into a DMZ can be near impossible. TBH that sounds like you decided to make things painful and then complain that they are painful.
- throw0101a 5y ago> It's not always possible to get certificates from Let's Encrypt for local network only services. In a big corporate environment jumping through the hoops necessary to deploy keys or get things into a DMZ can be near impossible. You're not wrong, but if you can go through the paperwork to add a CNAME to external DNS, your team can use DNS validation to verify host record ownership for LE/ACME: * https://github.com/acmesh-official/acme.sh/wiki/DNS-alias-mode https://github.com/acmesh-official/acme.sh/wiki/DNS-alias-mo... * https://www.eff.org/deeplinks/2018/02/technical-deep-dive-securing-automation-acme-dns-challenge-validation https://www.eff.org/deeplinks/2018/02/technical-deep-dive-se... * https://dan.langille.org/2019/02/01/acme-domain-alias-mode/ https://dan.langille.org/2019/02/01/acme-domain-alias-mode/ Seems not many people know about using dns-01 for internal-only hosts.